oss-sec mailing list archives
Re: [CVE Request] glibc iconv_open buffer overflow (was: Re: [oss-security] Re: glibc locale issues)
From: cve-assign () mitre org
Date: Wed, 13 Aug 2014 02:01:55 -0400 (EDT)
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
iconv/gconv_charset.h:strip() normalizes the transliteration argument to iconv_open, so the resulting file names follow a particular pattern, and there cannot be enough slashes to ascend to a writable directory.if not maybe the one byte overflow is still exploitable.Hmm. How likely is that? It overflows in to malloc metadata, and the glibc malloc hardening should catch that these days.Not necessarily on 32-bit architectures, so I agree with Tavis now, and we need a CVE. The upstream bug is: <https://sourceware.org/bugzilla/show_bug.cgi?id=17187>
Use CVE-2014-5119. A CVE-2005-#### number isn't needed because the msg00091.html message (referenced in 17187) does not state any security implications. - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (SunOS) iQEcBAEBAgAGBQJT6v7uAAoJEKllVAevmvmseTkIAMfWM1+WNFXL0zj5YmVAbl6e VzXYStCQinR6ilSaFQE52uar5CagHTcEXlvsOMgyB+SgVKDFNjlb4ClSdXIrJsPN CNVnG2kBwPMIYKYoddVk+wor4+HzhGfBMb9x59UzWFgyjtjo8oNL5rIIlVV06ta2 nX8MD4sk8b0aT0cNiahw59iH0raeGcvoGEJE9xweOTd9OU5psJUr3tw1qOXBTPTz uX8HJ8rWnxDEzFsAy4/qkNLAutoxwx0NXJgKul+xP5Tgg2KkdUWhu2rPm8Kb5swe v4IFlq8/TmItAClFdrGBv3/NwaGNubrfthEG0t7uuVQKy4FIIkVOvks7M98h1Ug= =B7sS -----END PGP SIGNATURE-----
Current thread:
- glibc locale issues Tavis Ormandy (Jul 13)
- Re: glibc locale issues Tavis Ormandy (Jul 13)
- Re: Re: glibc locale issues Florian Weimer (Jul 21)
- Re: Re: glibc locale issues Tavis Ormandy (Jul 21)
- [CVE Request] glibc iconv_open buffer overflow (was: Re: [oss-security] Re: glibc locale issues) Florian Weimer (Jul 29)
- Re: [CVE Request] glibc iconv_open buffer overflow (was: Re: [oss-security] Re: glibc locale issues) cve-assign (Aug 12)
- Re: Re: [CVE Request] glibc iconv_open buffer overflow (was: Re: [oss-security] Re: glibc locale issues) John Haxby (Aug 14)
- Re: Re: [CVE Request] glibc iconv_open buffer overflow (was: Re: [oss-security] Re: glibc locale issues) Tavis Ormandy (Aug 14)
- Re: Re: glibc locale issues Florian Weimer (Jul 21)
- Re: glibc locale issues Tavis Ormandy (Jul 13)